PC Pro

Zyxel ZyWall ATP100

This cost-effective security solution brings a good set of protection features to small businesses on a budget

- DAVE MITCHELL

SCORE

PRICE Appliance with 1yr Gold licence, £434 exc VAT from broadbandb­uyer.com

Not every business needs an enterprise-grade UTM. If you’re looking for something simpler and cheaper, Zyxel’s ZyWall ATP100 could well be the answer. Designed for small offices of up to 25 users, it borrows key features from Zyxel’s high-end USG series and adds cloud threat intelligen­ce, sandboxing and analytics, all for a price that’s very hard to argue with.

It comes in the form of a fanless desktop unit with one Gigabit WAN port, four copper LAN connectors and an SFP fibre socket for longer cable runs. Across these connection­s, Zyxel quotes a firewall throughput of 1Gbit/sec, dropping to 380Mbits/sec with all security services enabled.

The £434 asking price includes a year-long Gold licence, after which renewals cost £212 per annum. The licence enables all services, including web-content filtering, applicatio­n security, IDP, anti-spam, geoenforce­ment and the SecuReport­er web-based analytics and reporting service. The one box that’s notably unticked is cloud management, as Zyxel recently had to withdraw its SecuManage­r cloud management app due to security issues. This means that, for now, all ATP appliances can only be managed via their local web console, and there’s sadly no word on when or whether that will change.

Installati­on is swift, thanks to a wizard that enables internet access, installs the latest firmware and activates default security services. Since reporting data is stored in the cloud, you’re prompted to decide whether personal informatio­n such as email addresses and usernames should be uploaded; if not, you can still generate the full range of reports, but they’ll be anonymised.

For the best protection against malware, the anti-malware service can be set to operate in hybrid mode, which combines a local signature database with Zyxel’s online threat intelligen­ce to check whether downloaded files are safe. Any files that haven’t been seen before are automatica­lly dispatched to a cloudbased sandbox service for analysis: friendly files are allowed through, while those that are deemed a threat will be destroyed.

Another service you might want to customise is App Patrol, which le ts you control access to over 3,500 apps including webmail services, instant messenger platforms, Facebook and Twitter. To this, Zyxel’s web-content filtering adds over 100 categories of website that can be blocked; during testing, we found few sites slipped

“Any files that haven’t been seen before are automatica­lly dispatched to a cloud-based sandbox service for analysis”

past it. Unusually, it’s also possible to enable geo-enforcemen­t, by creating an address object for the region or country you want to block, then subjecting it to a security policy.

Enabling email protection is as easy as toggling on the sender-reputation and content-analysis features, and selecting whether suspect messages should be dumped or tagged for processing by local mail clients. The IDP, IP reputation and URL threatfilt­er services are even simpler to activate – a single click will do it, although you can pull up advanced settings and modify their behaviour should you so wish.

For everyday administra­tion, two dashboard views keep you in touch with the action. One presents a hardware status overview along with port traffic statistics; the other one, rather more excitingly, provides seven-day charts and graphs of all security activity, with details of top apps and any detected threats. The SecuReport­er service exposes a wealth of informatio­n about all web, app and threat activity, with the Analyzer page providing insights into security indicators, sandbox activity, traffic and users at risk. Custom reports can be sent to multiple recipients at regular intervals.

Network gateway protection is a must for any business, and the ZyWall ATP100 is a worthy choice. The lack of cloud management means it’s not suitable for companies with workers spread across multiple sites, but the range of security measures on hand is persuasive, especially considerin­g the price.

SPECIFICAT­IONS

Fanless desktop chassis dual-core CPU 1GB RAM 6 x Gigabit Ethernet (WAN, 5 x LAN) USB 3 RJ-45 serial port external PSU 216 x 148 x 33mm (WDH) 1yr Gold licence web browser management

5yr limited warranty

 ??  ??
 ??  ?? BELOW The reporting service and dashboard provide a wealth of revealing informatio­n
BELOW The reporting service and dashboard provide a wealth of revealing informatio­n
 ??  ?? ABOVE The Zyxel’s five Ethernet ports are joined by an SFP fibre connector
ABOVE The Zyxel’s five Ethernet ports are joined by an SFP fibre connector

Newspapers in English

Newspapers from United Kingdom